Impact
The ReadDataElement function in common.c performs an incorrect bounds check, allowing a local attacker to read memory outside the intended limits. This error can be exploited without requiring additional privileges or user interaction, leading to the disclosure of sensitive data stored in device memory or shared with local applications. Because this flaw is rooted in improper memory handling, it falls under CWE‑120 and represents a classic local information disclosure vulnerability.
Affected Systems
All Android devices that include the vulnerable implementation of common.c are affected, regardless of exact OS version. The flaw is present in any build or update that does not contain the corrected bounds check. While specific version numbers are not documented in the advisory, any unpatched Android release that has not incorporated the recent security update remains at risk.
Risk and Exploitability
The CVSS score is 6.2, indicating moderate severity. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low but nonzero likelihood of widespread exploitation. The attack vector is local; any user or locally installed application can trigger the flaw without user interaction. Consequently, the primary risk is confidentiality loss rather than denial of service or code execution.
OpenCVE Enrichment